Config Pages Viewer - Critical - Access bypass - SA-CONTRIB-2025-086
Project: Config Pages ViewerDate: 2025-July-02Security risk: Critical 15 ∕ 25 AC:None/A:None/CI:Some/II:None/E:Theoretical/TD:AllVulnerability: Access bypassAffected versions: <1.0.4CVE IDs: CVE-2025-7031Description: This module enables you to use config_pages as a content entity.
The module doesn't check permission or entity access before rendering config_pages content.Solution: Install the latest version:
- If you use the Config Pages Viewer module at version 1.0.3 and lesser, upgrade to Config Pages Viewer 1.0.4.
Reported By:
Fixed By:
Coordinated By:
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team